Summary
CVE-2026-77550 is a critical improper neutralization of CRLF sequences (CRLF injection, CWE-93) vulnerability affecting devices and software running Ubiquiti UniFi OS, including UniFi OS Server. A network-based attacker can exploit the flaw to bypass authentication on affected UniFi OS devices or instances without any privileges or user interaction. The vulnerability carries a maximum CVSS v3.1 base score of 10.0 and was disclosed by Ubiquiti in Security Advisory Bulletin 067.
Technical details
- Root cause: improper neutralization of CR/LF sequences (CWE-93) within UniFi OS request/response handling.
- Trigger conditions: no authentication or user interaction required; low attack complexity.
- Attack vector: network-based, exploitable remotely against any exposed UniFi OS instance.
- Impact: complete authentication bypass on the affected UniFi OS device or instance, enabling unauthorized access to management functions.
Affected software
- UniFi OS Server: versions prior to 5.1.37
- Cloud Keys: versions prior to 5.1.31
- Network Video Recorders: versions prior to 5.1.31
- Enterprise Network Video Recorders: versions prior to 5.1.31
- Enterprise Network Attached Storage: versions prior to 5.1.31
- Dream Machines: versions prior to 5.1.31
- Enterprise Firewall Core: versions prior to 5.1.31
- Dream Routers: versions prior to 5.1.31
- Enterprise Fortress Gateway: versions prior to 5.1.31
- Cloud Gateways: versions prior to 5.1.31
- Dream Wall: versions prior to 5.1.31
- Express 7: versions prior to 5.1.31
- Network Attached Storage: versions prior to 5.1.32
- Express: versions prior to 4.0.17
Severity
CVSS v3.1 Base Score: 10.0 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade affected products to the patched versions specified by Ubiquiti — UniFi OS Server to 5.1.37 or later, most Cloud Key/NVR/Gateway/Dream Machine product lines to 5.1.31 or later, Network Attached Storage to 5.1.32 or later, and Express appliances to 4.0.17 or later.
- If immediate patching is not possible: Restrict network exposure of UniFi OS management interfaces to trusted networks only, and remove direct internet exposure of UniFi OS Server/console login and management endpoints until patched.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
UniFi OS

